New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
wait is this biloh guy actually involved in cc or hostpapa? why are demands being made to this guy. excuse me for being ignorant here
HostPapa owns ColoCrossing
https://www.linkedin.com/in/jon-biloh
As far as I know @jbiloh is at least remotely related to CC ("consultant" or similar). And anyway AFAIK he founded CC, so I guess he does care whether they risk to go belly up ...
Yeah ColoCrossing owns LowEndTalk and LowEndBox, @jbiloh is an employee of CC and the admin of LET
yeah I knew the part where cc is owned by hostpapa who seems at least partially involved in a few shit shows now
are you serious...? this is owned by a company? that i didn't know at all. what the fuck?
that is only mildly concerning
From what I understand (which could explain your situation), three brands under ColoCrossing. HudsonValleyHost, ChicagoVPS, and ColoCrossing Cloud were using a shared Virtualizor panel. Based on details shared earlier in this thread, between all brands, and aggregate of 10k virtual machines were affected.
It seems ColoCrossing's primary business itself, including its dedicated server and colocation customer portal (portal.colocrossing.com), as well as its billing and support systems, were not impacted. We aren't seeing any indicators, and operations there are smooth sailing for that separate platform.
If you're wondering whether your hosting provider uses Virtualizor, you can check by looking at the port in your control panel’s URL. If it uses port :4083, that’s a sign the control panel is running on Virtualizor. If your provider is running on Virtualizor, it might be worth checking in with them to confirm they haven't recently engaged with Virtualizor Support in any manner that would require sharing credentials with their team. This is quite messy in general. Wishing all affected a speedy recovery, and if you haven't backups are recommended too.
has there been any official release statement or are we just totally ignoring this until it doesn't blow over?
..but it wouldn’t be too bad if you shared it in dm, for educational purposes?
Yeah, I got a cheap dedi from CC from their BF sales (needed lots of ram for a short project that was taking place over xmas) and also got a vps just to try them out. I actually used a different email addresses between the two since they were different systems and I only got the mail on the VPS one so it seems that it's just their cloud/vps.
P.S. Happy Racknerd isn't impacted!
wow 10k vm's affected...
Mind putting together a quick list of the companies you're using? Just making sure we're not... spiritually aligned.
BWAHAHAHAHAHAHA OMFG ok this was funny i wish you a $7/y deal
If you are reading this and you can still access your data, backup now!
Backup fast!
Edit: forgot the popcorn gif...
Just got to the end of reading this thread and was going to say exactly this!
There's no indication the network isn't still compromised, or that the attackers don't intend to sabotage/steal data from the VMs, (in fact all indications suggest they may), so rescue your data and trigger an OS reinstall so they have nothing to steal and blackmail you with
they will never be able to blackmail me over my love of Sopranos
yeah, none of the data on my VPS is worth while but I did just trigger a wipe. First a reinstall image with a lame password and then a good ol dd zero to vda before shutting it down, I can deal with it after CC comments/etc
Hopefully others are lucky enough to backup their data (really, they should have been already and if not, this is a wake up call for them) and don't need the VPS up.
It's Memorial Day long weekend in USA so @jbiloh is probably at the cottage on Lake Michigan, counting his money right now.
Fucking missed 10 pages.
And how tf CC give Bean Man a b-day gift like this.
This iz a crime officers!
@nghialele nigalee
Would anyone (not me, lazy) compile a list of Virtualizor using hosts?
if they dont under virtfusion I don't want them
This isn't true.
There is evidence they compromised several VMs in the process (including ours). They also dumped the entire Virtualizor DB and sent it to several people. This wasn't "limited system metadata."
o_o
@Lunar said:
Of course they'd say some shit like this 6 hours after a breach, damage control whereas they've definitely been able to check that 10.5k VMs were not comped in that 6 hours!
Who in the world do this? T_T
After climbing thru 10 pages, I'll take some bro advice, especially from @zGato for how insane each host a diff key pairs
My data is with crankbis, I'm safe.